Court, Explained
U.S. Federal District Courts
Back to docket
N.D. Cal.MixedFiled Aug. 21, 2026

Asercion v. Salon

Judge
Lin
Docket
3:26-cv-02442
Court
U.S. District Court · Northern District of California
Pages
10
Civil RightsMotion to DismissConsumer CreditFirst Amendment
In one sentence

In Asercion v. Ulta Salon, Judge Lin allowed most of plaintiff's website-tracking privacy claims to proceed but dismissed the California consumer protection claim for lack of economic injury.

Who this affects

People who visit retail websites and are concerned about browser tracking technology, targeted advertising, and the use of their online browsing data by companies and third parties. Also relevant to companies that use third-party tracking tools on their websites and rely on privacy policy disclosures as a consent mechanism.

What happened

In Asercion v. Ulta Salon, Cosmetics & Fragrance, Inc., No. 26-cv-02442, plaintiff Arny Asercion sued Ulta alleging that its website embedded code that installed tracking technology on visitors' browsers during his May 2025 visit, allowing Ulta and third parties to track his browsing activity, build detailed user profiles, and facilitate targeted advertising. Asercion brought claims under California's wiretapping and privacy law (CIPA), the federal Wiretap Act, California's computer fraud law (CDAFA), the California Constitution's privacy guarantee, and California's Unfair Competition Law (UCL). Ulta moved for judgment on the pleadings, asking the court to dismiss all claims.

The court found that Asercion adequately alleged the core facts supporting most of his claims. On the CIPA and federal Wiretap Act claims, the court found sufficient allegations that trackers collected the actual content of his browsing — such as product views — in real time, and that Ulta knowingly aided third-party collection for targeted advertising. The court also found adequate allegations under CDAFA, concluding that installing trackers on a user's browser without permission qualifies as unauthorized computer access. The California constitutional privacy claim survived as well, because allegations of internet-wide tracking producing detailed user profiles raised sufficiently serious privacy concerns at this stage. The court rejected Ulta's consent defense, finding that the mere existence of a privacy policy does not establish consent, particularly where the trackers may have been installed before the user could have seen the policy.

Judge Lin granted Ulta's motion in part and denied it in part. The UCL claim was dismissed because Asercion's allegations that his data had economic value were too conclusory to establish the economic injury required for standing under that law. However, the UCL claim was dismissed with leave to amend, meaning Asercion may file a revised complaint by September 11, 2026, to attempt to cure that deficiency. All other claims — under CIPA, the federal Wiretap Act, CDAFA, and the California Constitution — survived and will move forward.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Asercion v. Salon · No. 3:26-cv-02442
Judge
Lin
Date
Aug. 21, 2026

Background

Plaintiff Arny Asercion alleges that defendant Ulta Salon, Cosmetics & Fragrance, Inc. embedded code in its website that caused internet tracking technology — trackers — to be installed on visitors' browsers. According to the complaint, these trackers allowed both Ulta and third parties to monitor users' browsing activity on the Ulta website and across the broader internet, enabling targeted advertising and the creation of detailed user profiles. Asercion alleges he visited the Ulta website in May 2025 to browse for Mother's Day gifts, and that the trackers were installed on his browser at that time.

Asercion filed suit asserting five claims: (1) Section 631(a) of the California Invasion of Privacy Act (CIPA), California's wiretapping statute; (2) Section 638.51(a) of CIPA, which prohibits the use of "pen registers" — devices or processes that record routing or addressing information but not communication content — without court approval; (3) the federal Wiretap Act, 18 U.S.C. § 2511; (4) the California Comprehensive Computer Data Access and Fraud Act (CDAFA), Cal. Penal Code § 502; and (5) California's Unfair Competition Law (UCL). Ulta moved for judgment on the pleadings, which is a pretrial motion asking the court to rule that the complaint fails as a matter of law based solely on the pleadings filed.

CIPA Section 631(a) — Wiretapping

Ulta argued that Asercion failed to allege (a) interception of communication contents by a third party, and (b) that Ulta aided and abetted such interception with the required intent.

Interception and contents

The court found that Asercion's allegation that trackers collected and transmitted browser activity "in real time" satisfies the requirement that interception occur contemporaneously with transmission. The court also found that allegations of product views constitute "contents" — the intended message of a communication — rather than mere routing or addressing information. The court rejected Ulta's argument that Asercion needed to allege some "substantive communication" beyond a website visit, finding it reasonable to infer that browsing for Mother's Day gifts involved actions like searching or clicking on product pages.

Aiding and abetting

The court held that Asercion's allegations that Ulta "causes" installation of third-party trackers and then uses them to collect and transmit information to third parties support a reasonable inference that Ulta had the required knowledge and purpose. Dismissal of the Section 631(a) claim was denied.

CIPA Section 638.51(a) — Pen Registers

Ulta raised five arguments for dismissal of the pen register claim, all rejected:

1. Contents vs. routing information: Ulta argued that because trackers collected content, they fall outside the pen register definition (which covers only routing/addressing information, not content). The court found that different components of the same tracker could collect different types of information — some content (not pen registers), others IP addresses (pen registers) — and that the statute's reference to a "process" covers individual tracker components.

2. No specific allegation of use during Asercion's visit: The court found it reasonable to infer that trackers meeting the pen register definition were installed during Asercion's visit, given his allegation that the website installs numerous trackers when users visit.

3. Telephone-only scope: Ulta argued the pen register statute applies only to telephone technology. The court rejected this, citing authority — including Ulta's own cited cases — holding it applies to internet technology.

4. Statutory standing: The court found Asercion adequately alleged injury because the pen register trackers enable construction of detailed user profiles, and it is reasonable to infer that happened to him.

5. Intent requirement: The court found no intent requirement in the text of Section 638.51(a) and noted Ulta cited no authority for this proposition.

Dismissal of the Section 638.51(a) claim was denied.

Consent Defense (Both CIPA Claims)

Ulta argued that its website privacy policy established Asercion's consent to the tracking. The court rejected this argument on two grounds. First, the mere existence of a privacy policy does not establish that Asercion actually saw or agreed to it. Second, the court found it reasonable to infer that the trackers were installed when Asercion first visited the website — before he could have encountered or read the privacy policy. Whether there was some "mechanism" on the website to provide consent is a factual question the court declined to resolve at the pleading stage.

Federal Wiretap Act

Ulta raised four arguments, all rejected:

1 and 2. The court incorporated its earlier rulings that Asercion sufficiently alleged real-time interception of communication contents.

3. Specificity of vendor allegations: Ulta argued the complaint failed to identify which vendor intercepted which specific communication and whether vendors acted as independent interceptors. The court found the complaint identifies specific trackers by vendor and that it is plausibly inferred that some were installed during Asercion's visit.

4. Party exception and crime-tort exception: The federal Wiretap Act contains a "party exception" providing that a party to a communication does not intercept it within the statute's meaning. However, this exception does not apply when the intercepting party acts with an independent criminal or tortious purpose beyond the interception itself (the "crime-tort exception"). The court found the crime-tort exception applies here because Asercion adequately alleged Ulta intended to collect and distribute user information for targeted advertising — an independent tortious purpose — and that doing so allegedly violated CIPA.

Dismissal of the federal Wiretap Act claim was denied.

CDAFA — Computer Fraud

Ulta raised three arguments for dismissal, all rejected:

1. Injury: Asercion's allegation that Ulta unjustly enriched itself by using his unlawfully accessed data was found sufficient.

2. "Without permission" requirement: Ulta argued this element requires allegations that the defendant overcame a technical or code-based barrier. The court rejected this, reaffirming its prior holding that inserting third-party code into a website that allows data collection without the user's permission suffices.

3. Specificity of alleged violations: The court analyzed each relevant subsection of Cal. Penal Code § 502(c) and found all were adequately pleaded: (c)(1) (wrongful use of data to obtain property), (c)(2) (unauthorized copying or use of data), (c)(4) (adding software without permission by installing trackers), (c)(6) (providing means of access to a computer system), and (c)(7) (unauthorized access to a computer).

Dismissal of the CDAFA claim was denied.

California Constitutional Privacy Claim

To state this claim, a plaintiff must allege: (1) a legally protected privacy interest; (2) a reasonable expectation of privacy; and (3) an intrusion so serious as to constitute an egregious breach of social norms — i.e., highly offensive conduct.

The court found Asercion's allegations of internet-wide tracking producing detailed user profiles sufficient on both the reasonable expectation of privacy and highly offensive elements, noting these are fact-intensive inquiries generally inappropriate to resolve at the pleading stage. The alleged installation of 201 trackers bolstered the offensiveness finding. The court rejected Ulta's privacy policy argument for the same reasons stated above.

Dismissal of the California constitutional privacy claim was denied.

UCL Claim

California's Unfair Competition Law requires a plaintiff to demonstrate economic injury to have standing to sue. Asercion argued that his personal data has economic value and that Ulta monetized it without his consent. The court found these allegations too conclusory to establish the required economic injury and dismissed the UCL claim. Because Asercion lacked statutory standing, the court did not address Ulta's other arguments for dismissal of this claim.

The UCL claim was dismissed with leave to amend.

Disposition

The motion for judgment on the pleadings was granted in part and denied in part. The UCL claim was dismissed with leave to amend. All other claims — CIPA Sections 631(a) and 638.51(a), the federal Wiretap Act, CDAFA, and the California constitutional privacy claim — survived. Asercion may file an amended complaint by September 11, 2026, limited to correcting the UCL deficiency. Ulta must respond by October 2, 2026.

The authoritative version

Read the full 10-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.